On 14-15 September 2026, Parliament's Joint Committee on Human Rights (JCHR) published Human Rights and the Regulation of AI. It calls for a dedicated AI Bill built on a risk-based regime. The regime would sit under a single independent statutory regulator with powers to set standards and enforce them. It would also include pre-release approval for high-risk systems, due-diligence duties across the AI supply chain, and outright bans on subliminal manipulation and inappropriate biometric profiling. Chair Alex Sobel MP said the UK is unprepared for AI's consequences and called for a regulator "with the teeth to ensure enforcement", according to Legal Cheek's report.
The strongest case for the committee
The committee's core diagnosis deserves a fair hearing. It finds that existing UK law is fragmented and puts too much responsibility on the organisations deploying AI rather than the companies that design and build it. Regulators also lack powers to test some systems before release or to stop those posing unacceptable risks. Legal Cheek reports the committee's concern that people may not even know AI played a role in a decision affecting them. That undermines the right to an effective remedy, which is a serious problem whatever one thinks of regulation. A hospital trust or a council buying an opaque scoring tool cannot audit a model it did not build, and an ex post complaint to a regulator is a poor substitute for a fault caught in testing.
The transparency point is the strongest. A duty to tell people when AI has significantly shaped a decision about them, and a route to contest it, is cheap to comply with and directly protects individual rights. It also fits the committee's call to strengthen the UK GDPR's safeguards on automated decision-making, which builds on legal machinery that already exists.
Where the design overreaches
The weaker parts are the institutional ones. The government's own framing is that the UK's "pro-innovation approach to regulation is a source of strength relative to other more regulated jurisdictions", as the AI Opportunities Action Plan put it in January 2025. That plan set out 50 numbered recommendations. Eight of them (23-30) were about regulators, including funding them to build AI capability, embedding a pro-innovation focus in guidance and expanding sectoral sandboxes. The JCHR proposal cuts against that architecture. It would replace it with one new body and a gate that high-risk systems must clear before they reach the market.
Pre-deployment approval is the hardest element to defend. It works for medicines because the harm is bounded, the endpoint is measurable and the product is fixed. General-purpose models and the applications built on them are none of these. "High-risk" would be defined by statute, but the same model can power a homework helper and a benefits-triage tool. An approval regime would either be so broad that it queues up thousands of routine deployments, or so narrow that it misses the harms the committee cares about. Both failures fall hardest on small UK developers and public bodies, who have no compliance department to absorb months of delay. Large incumbents can.
The bans are easier to accept in principle. Subliminal manipulation and indiscriminate biometric profiling are narrow, identifiable practices, and prohibiting a small set of clearly defined harms is proportionate. The risk is drafting: a vague ban on "inappropriate" profiling invites litigation over legitimate uses such as fraud detection, accessibility tools and age assurance, and it can chill lawful speech-adjacent products.
A single regulator is not obviously the fix
The committee treats fragmentation as an argument for consolidation. But the fragmentation reflects the fact that AI is a general-purpose technology used in finance, health, employment and policing. Those sectors have regulators with domain knowledge, and a new AI regulator would have to either duplicate them or override them. The more evidence-based route is to give existing regulators clear, common powers and a duty to cooperate, backed by a small central function for cross-cutting risks and pre-release testing of the most capable systems. That is closer to what the government has said it wants.
The government has also spent much of the past two years deferring a comprehensive bill. Tech Monitor reported Peter Kyle's statement that legislation would be broadened and delayed, partly to address copyright and partly to align with the United States. The original plan was narrower: it would have required model evaluations through the AI Security Institute. The JCHR is effectively arguing that this delay has left rights protections thinner than they should be. That is a fair criticism of drift, even if its remedy is too heavy.
What a proportionate response looks like
The government should not adopt the report wholesale, but it should not ignore it either. Three steps follow from the evidence the committee gathered:
- Legislate the transparency and redress rights first. Notice, explanation and contestability for consequential automated decisions can be enacted quickly, and they protect people without gating products.
- Limit pre-deployment testing to a narrow class. Reserve it for the most capable frontier systems and a short list of clearly defined high-stakes public-sector uses, rather than a general approval regime.
- Define bans tightly. Any prohibition should name the conduct and carry an exemption test, so that legitimate fraud, safety and accessibility uses are not swept in.
The committee is right that rights protections should not depend on voluntary good behaviour by suppliers. It is wrong to assume the only way to secure them is a licensing bureaucracy. The UK's advantage is that it can legislate for outcomes people can enforce, while leaving room for the developers and adopters that the Action Plan is trying to attract. Parliament should take the transparency and redress recommendations now and make the government justify, with evidence, every proposal that would slow deployment.